Particle.news

Attackers Use ChatGPT Custom GPTs to Push ClickFix Lure and Install RAT

Hosting malicious Custom GPT pages on chatgpt.com and promoting them with paid Google ads gave attackers a credible entry that tricked users into running a PowerShell command that began a multi‑stage malware chain.

Overview

  • Security firm Huntress traced at least 40 incidents to the campaign and confirmed two infections that began on attacker‑created Custom GPT pages hosted on chatgpt.com.
  • The delivery path used sponsored Google search results to land victims on a Custom GPT that redirected them to a Google Sites page posing as a Cloudflare CAPTCHA which instructed users to paste and run a PowerShell command.
  • That command downloaded an MSI which launched a heavily obfuscated eight‑stage chain that sideloaded a legitimately signed host executable and loaded a loader hidden inside carriers such as WAV files or NuGet packages.
  • The final payload is a resilient RAT that supports remote desktop, camera and microphone capture, file search and drop‑and‑run of follow‑on payloads, uses DNS‑over‑HTTPS for command‑and‑control, and creates persistence via a Run key and a scheduled task named 'Canon Configuration Reader'.
  • OpenAI removed the first malicious Custom GPT on September 25 and a replacement appeared on September 27 as operators swapped signed hosts and carriers to evade takedowns, so Huntress urges behavior‑based detections and user training to block PowerShell→msiexec MSI installs, signed apps running from unusual AppData folders, and reappearing Run/task persistence.